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(54) Device security mechanism based on registered passwords 



(57) The BIOS device (108) or some other secure 
store of a portable computer (PC 1 00) or other valuable 
device stores a password-based security program 
(302), an encrypted password (306), and an encryption 
key (304). When the PC is booted, the security program 
executes first and prompts the user for a password* en- 
crypts it with the stored key, and compares It with the 
stored password. If the passwords do not match, boot 
is aborted and the PC Is disabled. Only If the passwords 
do match Is boot continued and use of the PC enabled. 
If this security measure is advertised, theft of the PC is 
deterred because of the difficulty of accessing or by- 
passing the password and the security program in the 



BIOS device. The encrypted password is also registered 
with a remote trusted certificate authority (TCA 150) or 
Is stored on a local external storage device (250). To 
establish or change the password, a communication 
connection Is established from the PC to the TCA or 
storage device. If a password already exists In the PC, 
It is compared against the password stored by the TCA 
or the storage device. If they match, or if a password 
does not yet exist, the user is prompted for a new pass- 
word, which is then encrypted and stored In both the BI- 
OS device and the TCA or storage device. The pass- 
word is also available for retrieval from the TCA or stor- 
age device in case the user forgets it. 
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Description 
Technical Field 

[0001] This invention relates generally to security 
mechanisms for thwarting theft or unauthorized access 
of devices, and particularly to password mechanisms. 

Background of tlie Invention 

[0002] Electronic devices of all sorts are targets for 
thieves because of their typically-high value-to-size ra- 
tio. Portable computing devices, such as notebook com- 
puters, are particularly vulnerable to theft because they 
are so small, valuable, and portable. Conventional se> 
curity measures are based on physical restraints that 
use anchoring devices and locked enclosures. But 
these limit portability and convenience of use. If the de- 
vices could be made useless to anyone but the owner, 
and advertised as such, they would lose their value to, 
and hence not be as much of a target for, thieves. This 
implies the use of some sort of a password system that 
cannot be defeated easily. But conventional password 
mechanisms are inadequate. 

[0003] Software-based password systems are used 
in portable computers today to restrict access, but they 
can be defeated either by reinstalling the operating sys- 
tem software or, in some cases, by even simpler actions, 
such as exploiting loopholes in the operating systems 
that support them (e.g. the "Safe Mode" in Windows 95). 
Nevertheless, providing a password on power-up of a 
computer is the simplest way to validate a user. Hard- 
ware-based security systems (e.g. those available on 
some car radios) support password control, but if the 
password is lost, only major hardware surgery allows 
the device to be activated again. Providing a cost and 
effort barrier to defeating the password system is essen- 
tial, but it should be easier to deal with lost passwords 
and allow validation of the device by some authority. 
Public Encrypted Signatures are used to authenticate 
received information as having been legitimately provid- 
ed by a user. Coding and encrypting of the password by 
using an assigned public key can serve as a means of 
ensuring that one is dealing with a unique registered de- 
vice. Trusted Certification Authorities exist to provide 
registered digital signatures and to maintain user regis- 
tration infomiation. They can be used to register signa- 
tures for coding messages. But none of these existing 
capabilities alone provides an adequate security mech- 
anism for portable devices. 

Summary of the Invention 

[0004] The inventors have recognized that there are 
several requirements for a security system for portable 
devices: 

• The security system should add little or no cost to 



the device either in parts or in manufacture, and it 
should not cause any additional expense to the dis- 
tribution system. 

• The cost, in effort or money, to defeat the security 
5 system should approach or exceed the value of the 

device. 

• Access to the device should be individualized to the 
owner, yet allow ownership to be transferred without 
great difficulty. 

10 • The security system should use existing hardware, 
software, and security technologies and preferably 
be suitable for installation on existing computers. 

• Any individualized information used in the security 
system should be able to be archived by some au- 

15 thority that could intervene if legitimate access to 
the device needed to be reestablished. 

• The security system should be attractive enough to 
become a standard and thus become supported 
economically by both device vendors and third par- 

20 ties. 

[0005] Accordingly, this invention is directed to solv- 
ing the problems and disadvantages and meeting the 
requirements of the art. Generally according to the in- 
25 vention. a device security apparatus comprises the fol- 
lowing items. Storage in the device for storing a pass- 
word. The storage must be secure, in that it prevents a 
user of the device from accessing (i.e., extracting and/ 
or changing) the stored password while use of the de- 
30 vice is disabled. One example of such storage is the BI- 
OS device which stores the BIOS program of a personal 
computer. Another item is a connector for connecting 
the device to an external entity such as a local memory 
device or a remote trusted authority. Examples of such 
35 connectors include an input and output port and a net- 
work communications port of a personal computer. An- 
other item is a lock in the device that is cooperative with 
the storage and disables use of the device unless a 
password is given to the lock which corresponds to the 
40 stored password. The lock may illustratively be imple- 
mented as a program that also resides in secure mem- 
ory, e.g., in the BIOS device, along with the password. 
Another item is an arrangement that cooperates with the 
storage, the connector, and the lock, and responds to 
45 the use of the device having been enabled and the con- 
nection having been made to the external entity by en- 
abling the stored password to be changed if the stored 
password corresponds to a password stored by the con- 
nected external entity, and by effecting storage of the 
50 changed password by the external entity. This arrange- 
ment may also illustratively be implemented as a pro- 
gram, but it need not be stored in secure storage. 
[0006] The invention may be implemented to satisfy 
some or all of the requirements set out in the Back- 
55 ground section: 

1 . It adds no cost in parts to the device, with the 
possible exception of a guaranteed communication 
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capability. (But most intelligent devices such as 
computers already have a modem). It does add one 
step in manufactunng: that of selecting the insecure 
start-up mode, to install other software. 

2. Defeating this security system would require that 
the device be opened and the secure storage (e.g., 
computer BIOS memory) be physically disconnect- 
ed and re-written. This is not a simple or a cheap 
task. 

3. Not only is the device ownership individualized, 
but also it can be transferred or changed in a secure 
manner. 

4. No new technology is required. In fact, it might 
be possible to add this capability to some existing 
intelligent devices, such as computers. 

5. A trusted authority is used.to manage and control 
security and provides a valued service. Alternatives 
to the trusted authority can use a local plug-in de- 
vice like a PC card to act in place of the trusted au- 
thority and provide a more local version of the sys- 
tem. 

6. Because the invention can be Implemented to 
satisfy all of the above-mentioned requirements, It 
may be attractive as a standard and/or a widely-de- 
ployed commercial capability. 

[0007] These and other features and advantages of 
the present invention will become more apparent from 

the following description of an illustrative embodiment 
of the invention considered together with the drawing. 

Brief Description of the Drawing 

[0008] 

FIG. 1 is a block diagram of a computer network that 
includes a first illustrative embodiment of the inven- 
tion; 

FIG. 2 is a block diagram of a computer that in- 
cludes a second illustrative embodiment of the in- 
vention; 

FIG. 3 Is a block diagram of contents of a BIOS de- 
vice of portable computers of FIGS. 1 and 2; 
FIGS. 4-6 are a functional flow diagram of opera- 
lions of a security program of the portable comput- 
ers of FIGS. 1 and 2; and 
FIG. 5 additionally includes a functional flow dia- 
gram of operations of a trusted certificate authority 
of the computer network of FIG. 1 . 

Detailed Description 

[0009] FIG. 1 shows a portable computer (PC) 100 
that includes a central processing unit (CPU) 102, a 
read-only memory (ROM) 104, a random access mem- 
ory (RAM) 106, a basic input and output operating sys- 
tem (BIOS) device 108. and a disk memory 112, all in- 
terconnected by a memory bus 114. PC 100 further In- 



cludes an input and output (I/O) interface 116 that com- 
prises a data network interface 120 and/or a modem 
122, connected to CPU 102 by an I/O bus 118. An alter- 
native embodiment of PC 100 where I/O interface 116 

5 comprises an I/O port 220 is shown in FIG. 2. As de- 
scribed so far, PC 100 is conventional. PC 100 may be 
any device that has a storage element like BIOS device 
108: one whose contents cannot be easily accessed 
(extracted or changed) or bypassed by a user of the de- 

10 vice while operation of the device is disabled, and whose 
operability hinges on those contents. 
[001 0] BIOS device 1 08 comprises non-volatile, "per- 
manent", memory, one whose contents are preserved 
even when power is absent. Unlike ROM 104, however, 

15 it is electrically alterable and programmable under con- 
trol of special software, in order to update BIOS over the 
life of PC 100. Storage devices of this type are known 
as programmable read-only memory (PROM), electri- 
cally-erasable PROM (EEPROM), or flash memory. 

20 When PC 100 is booted, e.g., powered up, CPU 102 
begins to execute instructions out of ROM 104. These 
instructions cause CPU 1 02 to transfer the contents (the 
BIOS program) of BIOS device 108 into RAM 106 and 
to execute those contents out of RAM 106. Execution of 

25 the BIOS program boots PC 100. PC 100 cannot be 
booted without the BIOS program. And if PC 100 cannot 
be booted, the BIOS program cannot be updated or al- 
tered. So. if contents of BIOS device 118 get "corrupt- 
ed", either BIOS device 118 must be replaced, or PC 

30 100 must be returned to the manufacturer who can 
physically bypass the normal electrical connections to 
BIOS device 118 and reprogram It. This is also conven- 
tional. 

[0011] The contents of BIOS device 1 08 are shown in 

35 FIG. 3. According to the invention. BIOS device 108 im- 
plements a security mechanism for theft deterrence. In 
addition to containing the conventional BIOS program 
300, device 108 also contains a security program 302 
including encryption key 304 and password 306 entries. 

"^0 Security program 302 is appended to the beginning of 
BIOS program 300 so that at boot time it is loaded into 
RAM 1 04 either prior to or along with BIOS program 300 
and is executed prior to completion of the execution of 
BIOS program 300. 

45 [0012] The basic concept of the security mechanism 
is to have a unique password 306 stored in BIOS device 
108 and require that password 306 be entered and 
matched from the keyboard or other I/O device at the 
very beginning of each boot (e.g., power-on) cycle to 

50 allow the boot cycle and subsequent PC 1 00 operation 
to continue. A mismatch of password 306 Is a functional 
equivalent of a "corrupt" BIOS program 300. Conse- 
quently, PC 100 is of no use to anyone who does not 
have password 306. And overriding of the security 

55 mechanism is very difficult. It requires either that BIOS 
device 108 be replaced with a new one, or that PC 100 
be returned to the manufacturer who can physically by- 
pass the normal electrical connections to BIOS device 



3 



5 



EP1 111 495A1 



6 



108 and reprogram it. This makes PC 100 economically 
not worth stealing, and hence deters theft. 
[0013] On the one hand, the security mechanism 
must be robust enough to make its breach or override 
too difficult to be worthwhile. On the other hand, the se- 
curity mechanism has to be flexible enough to allow use 
of the machine to be restored if the password is forgotten 
and to allow security to be restored if the password is 
compromised or the machine changes hands legiti- 
mately. For this purpose, the concept of the trusted cer- 
tification authority (TCA) 150 is introduced (see FIG. 1). 
[0014] TCA 150 is a repository of passwords and a 
service for passwords maintenance. It may be provided, 
for example, as a service to customers by the manufac- 
turer or vendor of PCs 100, or as a subscription for-fee 
service by a third party. As shown in FIG. 1 , a TCA 150 
comprises an I/O interface 152 to a communications 
network 130 (e.g., a data network or a telephone net- 
work) that allows TCA 150 to communicate with PCs 
100, a computer 154 that executes TCA service pro- 
grams, and a depository 1 56 (e.g.. a database) for stor- 
ing passwords and related information. 
[0015] In the alternative embodiment shown In FIG. 
2, a central TCA 150 is dispensed with, and each PC 
100 is provided with a security card 250 that provides 
TCA-substitute functionality for its corresponding PC 
100 only. Security card 250 comprises an I/O port 252 
that removably mates with (e.g., plugs into) I/O port 220 
of PC 100. and a memory 254. It is illustratively a PC- 
MCIA card or a floppy disk. 

[0016] A newly-manufactured PC 100 is not secure, 
in that it does not have a valid password 306 installed 
therein; rather, password 306 has a null value. This in- 
secure mode allows PC 100 to be initialized with soft- 
ware at the factory and to be tested without hindrance. 
PC 100 may also be sold without a valid password 306. 
But in order to deter theft of PC 1 00 prior to It being sold 
to an end user, PC 1 00 may be programmed with a valid 
password 306 prior to leaving the factory. In the latter 
case, the password must be communicated to the pur- 
chaser at time of sale, and either password 306 and in- 
formation Identifying the owner of PC 100 must be en- 
tered in depository 1 56 of TCA 1 50, or password 306 
must be entered in memory 254 of security card 250, as 
soon as possible. 

[0017] The functionality of security program 302 is 
shown in FIGS. 4 et seq. When execution of BIOS de- 
vice 108 contents begins, at step 400, e.g., upon power- 
up, CPU 102 activates the display and keyboard of PC 
100, at step 401. Since most BIOS programs 300 in- 
clude rudimentary display and keyboard drivers, step 
40 1 generally involves execution of that portion of BIOS 
program 300 that activates the display and keyboard. In 
the case of BIOS programs 300 that do not make the 
keyboard and display operable, step 401 involves exe- 
cution of a portion of security program 302 which either 
contains rudimentary display and keyboard drivers or 
which loads the display and keyboard drivers from disk 



and activates them. CPU 102 then executes program 
302 and first checks password 306 to determine if its 
value is null, at step 402. If It is not null, PC 100 is op- 
erating in a secure mode, and so CPU 102 prompts the 
5 user of PC 100 to enter the password, at step 404, illus- 
tratively by displaying a prompt to that effect on a display 
screen of PC 1 00. When the user responds, illustratively 
by typing the password on a keyboard of PC 100, CPU 
102 encrypts the received password with the stored en- 
cryption key 304, at step 406, and then compares the 
encrypted received password with password 306 which 
is also encrypted with key 304, at step 408, to determine 
If they match. If they do not match, CPU 102 halts the 
boot and further operation of PC 100, at step 410, ren- 
dering PC 100 unusable. If they do match, PC 100 is 
secure, and so CPU 102 completes booting PC 100, at 
step 411 . But prior to relinquishing control, program 302 
causes CPU 102 to prompt the user to indicate if he or 
she wishes to change the password, at step 412. If the 
user does not so indicate, as determined at step 414, 
PC 100 continues to operate conventionally but in a se- 
cure mode, at step 420. 

[0018] Returning to step 402, if password 306 is de- 
termined there to be null, it means that PC 100 is oper- 
ating in an insecure mode, and so CPU completes boot- 
ing PC 100, at step 415. But prior to relinquishing con- 
trol, program 302 causes CPU 102 to prompt the user 
to establish a valid password 306, at step 41 6. If the user 
elects not to establish a password, as determined at 
step 418, PC 100 continues to operate conventionally 
in the insecure mode, at step 420. 
[0019] In order to keep the security mechanism from 
being thwarted, steps 402-410 of security program 302 
are the only ones that need to be protected from bypass 
or override, because they constitute the security gate- 
way or lock that enables or disables (controls) operabil- 
ity of PC 100. Therefore, they are the only portion of 
program 302, along with password 306 and encryption 
key 304, that must be stored in a secure memory such 
as BIOS device 1 08. After that, the security gateway has 
been passed, either because the value of password 306 
is null or because the correct password was entered. In 
either case, the user is now free to use PC 100 in any 
way desired. Therefore, the remainder of program 302. 
which merely controls changing (including initial estab- 
lishment) of password 306, may be stored in any other 
memory of PC 100 where it can be accessed by CPU 
102. For example, if a floppy disk is in the disk drive. 
BIOS program 300 will attempt to complete the boot 
from it, as Is conventional in PCs, and so the remainder 
of program 302 may be stored on a floppy disk and ex- 
ecuted at this point to install or modify password 306. 
As will be seen below, password maintenance is func- 
tionally no different than upgrading or altering BIOS pro- 
gram 300, except that only a couple of entries 304 and 
306 of BIOS device 108 are changed and that commu- 
nications to the outside of PC 100 are taking place. 
[0020] Returning to consider the drawing, if the user 
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elects to change the password at step 414 of FIG. 4 or 
elects to establish a password at step 418, CPU 102 
proceeds to interact with either TCA 150 in FIG. 5 or 
security card 250 in FIG. 6. Turning first to FIG. 5, CPU 
102 establishes a connection to TCA 150 via network 
interface 120 and data network 130 (e.g., a LAN or the 
Internet) or via modem 1 22 and telephone network 1 30, 
at step 424, in a conventional manner. The requisite ad- 
dress of TCA 1 50 is either stored as a part of security 
program 302, or CPU 102 prompts the user to provide 
the address, at step 422. When the connection is estab- 
lished, at step 450, PC 100 and TCA 150 cooperate to 
establish the calling user's identity, at steps 426 and 
452. For example, TCA 150 asks questions of the user 
via network 1 30, the user answers them via PC 1 00, and 
TCA 150 compares the answers against information it 
has stored in depository 1 56 about the user to determine 
if there is a match. Alternatively, steps 426 and 452 may 
be dispensed with in the case of changing an existing 
password. When the user's identity is established to the 
satisfaction of TCA 150, TCA 150 requests the stored 
encrypted password 306 of PC 100, at step 454, and 
CPU 102 obliges by retrieving and returning password 
306, at step 428. If the received password 306 is not 
null, as determined at step 455, TCA 150 searches its 
depository 1 56 for this password and any information 
paired and stored in association therewith, including a 
user's identity, at step 456. If the password is found in 
depository 156, TCA 150 determines if its paired infor- 
mation matches the caller's identity that was determined 
at step 452. at step 458. If the stored identity and the 
calling user's identity do not match, TCA 150 sends a 
notice thereof and a denial of the transaction to PC 100, 
at step 460, and ends the transaction by breaking the 
connection to PC 1 00, at step 461 . Alternatively, if steps 
426 and 452 were not performed, TCA 150 merely 
searches depository 1 56 for the received password at 
step 456, and checks for presence of that password in 
depository 1 56 at step 458. When CPU 1 02 determines 
that the transaction has been denied, at step 430, it con- 
tinues conventional operation, at step 432, without a 
change of the password. Alternatively, CPU 102 ne- 
gates the boot-up and halts PC 1 00 at step 432, thereby 
rendering PC 100 useless. 

[0021] If the identity of the calling user was found to 
match the user identity stored by TCA 150 for password 
306 of this PC 100 at step 458, or if the received pass- 
word was found to be null at step 455, TCA 150 gener- 
ates a new private/public encryption key pair, at step 
466. and sends the public encryption key of the pair to 
PC 100, at step 468. CPU 102 receives the public en- 
cryption key, at step 436, and stores it in encryption key 
304 of BIOS device 108. at step 368, ovenA/riting any 
previous value of encryption key 304 in the process. 
CPU 1 02 then prompts the user for a new password and, 
upon receiving It, at step 440, encrypts the new pass- 
word with the stored encryption key 304, at step 442. 
Under control of the conventional special software for 



programming BIOS device 108, CPU 102 then stores 
the new encrypted password in password 306 of BIOS 
1 08, at step 444, ovenwriting any previous value of pass- 
word 306 in the process. Some BIOS devices may re- 

5 quire overwriting of the entire device in order to change 
any contents thereof, in which case either TCA 1 50 must 
supply the entire BIOS device contents with the new en- 
cryption key and password, or CPU 102 must read out 
the contents of the BIOS device to create an image 

10 thereof, change the encryption key and the password in 
the image, and then write the changed image back into 
the BIOS device. CPU 102 also sends the new encrypt- 
ed password to TCA 1 50, at step 446. PC 1 00 then pro- 
ceeds to operate conventionally, at step 448. TCA 150 

15 receives the new encrypted password, at step 470, and 
stores it and the private key of the newly-generated en- 
cryption key pair instead of the previous password and 
key with the caller identification information in deposito- 
ry 1 56, at step 472. TCA 1 50 then ends its operation, at 

20 step 474. 

[0022] If the user should ever forget the password, the 
user can retrieve it with the help of TCA 150. For exam- 
ple, the user calls an operator of TCA 150 and estab- 
lishes his or her identity to the operator in the manner 

25 of steps 426 and 452. Information about the user that is 
stored in depository 156 may include a voiceprint of the 
user, and the operator may use this voiceprint and the 
user's voice incoming on the call to authenticate the us- 
er. Once the user has been authenticated, the operator 

30 directs computer 154 to decrypt the user's password. 
Computer 154 does so by retrieving the user's encrypt- 
ed password and private encryption key from depository 
156 and using the private key to decrypt the password. 
The operator then reports the decrypted password to the 

35 user via the call, with an admonition to change the pass- 
word as soon as possible in case the call is not secure. 
[0023] If the user of PC 100 that is equipped with a 
security card 250, as in the embodiment of FIG. 2, elects 
to change the password at step 4 1 4 or elects to establish 

40 a password at step 418. CPU 102 proceeds to interact 
with security card 250 in the manner shown in FIG. 6. 
First, CPU 102 checks for presence of security card 250 
in I/O port 220, at step 600. If security card 250 is not 
connected to I/O port 220, CPU 102 prompts the user 

45 of PC 1 00 to make the connection, at step 602, and then 
returns to step 600. If and when CPU 102 determines 
at step 600 that security card 250 is connected to I/O 
port 220, it may optionally check, at steps 604-608, 
whether it is the correct security card 250 for this PC 

50 1 00, so as to prevent inadvertent destruction of a pass- 
word for another device. To perfonn this check, CPU 102 
retrieves from security card 250 the contents of memory 
254, at step 604, and compares these contents against 
password 306 to determine if they match, at step 606. 

55 If they do not match, CPU 1 02 prompts the user to con- 
nect the correct security card 250 to PC 100, at step 
608, and then returns to step 600. If and when it finds 
the correct security card 250 connected to PC 100, at 
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step 606. or if the check at steps 604-608 for the correct 
security card 250 is not performed, CPU 102 prompts 
for and receives from the user a new password, at step 
610, CPU 1 02 then encrypts the new password by using 
encryption l<ey 304, at step 612. Using public key en- 
cryption is not necessary, since there is no remote agen- 
cy like TCA 1 50 involved. Optionally, a common key can 
be used in all PCs 100, as Is common in most UNIX op- 
erating system environments, for example. Under con- 
trol of the conventional special software for program- 
ming BIOS device 108, CPU 102 then stores the new 
encrypted password as password 306 in BIOS device 
108, at step 614. CPU also stores it in memory 254 of 
security card 250 in place of any previously stored con- 
tents therein, at step 616. As in step 444 of FIG. 5, se- 
curity card 250 may need to supply the entire BIOS serv- 
ice 108 contents along with the new password. Alterna- 
tively or additionally, CPU 102 may store the unencrypt- 
ed password In memory 254 of security card 250. This 
has the advantage that, if the user ever forgets the pass- 
word, he or she can retrieve it (read and/or display it) 
from security card 250 via another machine that has a 
compatible I/O port 220. This presumes that the user 
can be counted upon to keep security card 250 physi- 
cally secure and separate from PC 100. CPU 102 then 
continues to operate conventionally. 
[0024] Of course, various changes and modifications 
to the illustrative embodiment described above will be 
apparent to those skilled In the art. For example, the in- 
vention may be Implemented differently on different de- 
vices (e.g., in manufacturer-specific or even model-spe- 
cific manner) so that, If the security of one implementa- 
tion should be breached. It will not affect all devices. For 
this purpose, a device (PC) serial number may be stored 
in ROM 104 and used to identify the manufacturer and/ 
or model. Such changes and modifications can be made 
within the scope of the invention and without diminishing 
its attendant advantages. It is therefore intended that 
such changes and modifications be covered by the fol- 
lowing claims except insofar as limited by the prior art. 



Claims 

1. A device (100) security apparatus CHARACTER- 
ISED BY storage (108) in the device for storing a 
password (306) and preventing a user of the device 
from accessing the stored password while use of 
the device is disabled; 

a connector (116) connecting the device to an 
external entity (150,250); and 
a lock (1 08) in the device, cooperative with the 
storage, that disables use of the device unless 
a password is given to the lock which corre- 
sponds to the stored password; and 
an arrangement (102:302-304) cooperative 
with the storage, the connector, and the lock, 



responsive to the use of the device having been 
enabled and the connection having been made 
to the external entity, for enabling the stored 
password to be changed if the stored password 
5 corresponds to a password stored by the con- 

nected external entity, and for effecting storage 
of changed said password by the external en- 
tity. 

10 2. The apparatus of claim 1 for a computer, wherein: 
the storage comprises a BIOS device (108) 
storing a BIOS program (300) of the computer and 
the password (306). 



the connector comprises a network communi- 
cations port (120) of the device; and 
the entity comprises a remote trusted authority 
20 (150). 

4. The apparatus of claim 1 wherein: 

the connector comprises an Input port (220) of 
25 the device; and 

the entity comprises a local storage device 
(250). 

5. The apparatus of claim 1 for a stored-program-con- 
30 trolled device, wherein: 

the lock comprises a stored program (302) 
that executes upon power-up of the device. 

6. The apparatus of claim 5 for a computer (100), 
35 wherein: 

the storage comprises a BIOS device (108) 
storing a BIOS program (300) of the computer, the 
password (306), and the lock program (302). 



40 7. The apparatus of claim 1 wherein: 

the arrangement Includes 

means (102:426) for establishing the user's 

Identity with the external entity, 

45 means (1 02:428) for providing the stored pass- 

word to the external entity, and 
means (1 02:436 et seq.) for enabling the stored 
password to be changed in response to receiv- 
ing an indication from the external entity that 

50 the established identity and provided password 

match an identity and the password stored by 
the external entity. 

8. The apparatus of claim 7 wherein: 

55 

the arrangement further Includes 

means (102:440-446) responsive to receipt of 

a new password from the user, for storing the 



15 3. The apparatus of claim 1 wherein: 
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new password in the storage and sending the 
new password to the external entity for storage. 

9. The apparatus of claim 1 wherein: 

5 

the storage stores an encrypted said password 
(306) and an encryption key (304); and 
the lock Is adapted to be responsive to receipt 
(404) of an unencrypted password by encrypt- 
ing (406) the received password with the stored io 
encryption key, comparing (408) the encrypted 
received password with the stored encrypted 
password, and disabling (410) use of the device 
if the compared passwords do not match. 

15 

10. The apparatus of claim 9 wherein: 

the arrangement includes 
means (102:426) for establishing the user's 
identity with the external entity, 20 
means (102:428) for providing the stored en- 
crypted password to the external entity, 
means (1 02:436 et seq. ) for enabling the stored 
password to be changed in response to receiv- 
ing an indication from the externa! entity that 25 
the established identity and provided password 
match an identity and the password stored by 
the external entity. 

means (102:438) for storing a new encryption 
key received from the external entity in the stor- 30 
age, and 

means (102:440-446) for encrypting a new 
password received from the user with the 
stored new encryption key, storing the encrypt- 
ed new password in the storage, and sending 35 
the encrypted new password to the external en- 
tity for storage. 
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